Stal_NT
|
Faced with an amusing trick siey "trinkets" to 3 machines in one institution of culture. Is distributed through the flash files (autorun.inf and Thumbs.db.exe). When you run the executable under WinXP is changing the desktop theme (background picture with the inscription hacked by kamba), bios screen (patch ntoskrnl.exe), there is a background image root folder (the same notorious inscription hacked by kamba). In the properties subject to change gives, but after a couple seconds back. Infection is sitting in the
WINDOWS system32 wbem cache files csrss.exe.
After removal of files gives back the desktop theme, no longer "pour" on the flash drive autorun.inf and thumbs.db.exe. At the root of the system drive delete desktop.ini (remove the background image), delete the following files:
WINDOWS system32 ofnimeo.dll
WINDOWS system32 oeminfo.ini
WINDOWS system32 oemlogo.bmp,
replace the patched ntoskrnl.exe. It seems to be.
Posted 602 days ago
|